mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 13:28:27 +00:00
Add orgId to reuse login1/login2 logic for LDAP 2nd step login
This commit is contained in:
@@ -370,16 +370,21 @@ export const ldapConfigServiceFactory = ({
|
|||||||
orgId,
|
orgId,
|
||||||
firstName,
|
firstName,
|
||||||
lastName,
|
lastName,
|
||||||
authMethods: [AuthMethod.EMAIL],
|
authMethods: [AuthMethod.LDAP],
|
||||||
isGhost: false
|
isGhost: false
|
||||||
},
|
},
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
await orgDAL.createMembership({
|
await orgDAL.createMembership(
|
||||||
orgId,
|
{
|
||||||
role: OrgMembershipRole.Member,
|
userId: newUser.id,
|
||||||
status: OrgMembershipStatus.Invited
|
orgId,
|
||||||
});
|
role: OrgMembershipRole.Member,
|
||||||
|
status: OrgMembershipStatus.Invited
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
|
||||||
return newUser;
|
return newUser;
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
email: z.string().trim(),
|
email: z.string().trim(),
|
||||||
|
orgId: z.string().optional(),
|
||||||
providerAuthToken: z.string().trim().optional(),
|
providerAuthToken: z.string().trim().optional(),
|
||||||
clientPublicKey: z.string().trim()
|
clientPublicKey: z.string().trim()
|
||||||
}),
|
}),
|
||||||
@@ -26,6 +27,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
handler: async (req) => {
|
handler: async (req) => {
|
||||||
const { serverPublicKey, salt } = await server.services.login.loginGenServerPublicKey({
|
const { serverPublicKey, salt } = await server.services.login.loginGenServerPublicKey({
|
||||||
email: req.body.email,
|
email: req.body.email,
|
||||||
|
userOrgId: req.body.orgId,
|
||||||
clientPublicKey: req.body.clientPublicKey,
|
clientPublicKey: req.body.clientPublicKey,
|
||||||
providerAuthToken: req.body.providerAuthToken
|
providerAuthToken: req.body.providerAuthToken
|
||||||
});
|
});
|
||||||
@@ -43,6 +45,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
schema: {
|
schema: {
|
||||||
body: z.object({
|
body: z.object({
|
||||||
email: z.string().trim(),
|
email: z.string().trim(),
|
||||||
|
orgId: z.string().optional(),
|
||||||
providerAuthToken: z.string().trim().optional(),
|
providerAuthToken: z.string().trim().optional(),
|
||||||
clientProof: z.string().trim()
|
clientProof: z.string().trim()
|
||||||
}),
|
}),
|
||||||
@@ -71,6 +74,7 @@ export const registerLoginRouter = async (server: FastifyZodProvider) => {
|
|||||||
|
|
||||||
const data = await server.services.login.loginExchangeClientProof({
|
const data = await server.services.login.loginExchangeClientProof({
|
||||||
email: req.body.email,
|
email: req.body.email,
|
||||||
|
userOrgId: req.body.orgId,
|
||||||
ip: req.realIp,
|
ip: req.realIp,
|
||||||
userAgent,
|
userAgent,
|
||||||
providerAuthToken: req.body.providerAuthToken,
|
providerAuthToken: req.body.providerAuthToken,
|
||||||
|
|||||||
@@ -130,10 +130,14 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
*/
|
*/
|
||||||
const loginGenServerPublicKey = async ({
|
const loginGenServerPublicKey = async ({
|
||||||
email,
|
email,
|
||||||
|
userOrgId,
|
||||||
providerAuthToken,
|
providerAuthToken,
|
||||||
clientPublicKey
|
clientPublicKey
|
||||||
}: TLoginGenServerPublicKeyDTO) => {
|
}: TLoginGenServerPublicKeyDTO) => {
|
||||||
const userEnc = await userDAL.findUserEncKeyByUsername(email);
|
const userEnc = await userDAL.findUserEncKeyByUsername({
|
||||||
|
username: email,
|
||||||
|
orgId: userOrgId
|
||||||
|
});
|
||||||
if (!userEnc || (userEnc && !userEnc.isAccepted)) {
|
if (!userEnc || (userEnc && !userEnc.isAccepted)) {
|
||||||
throw new Error("Failed to find user");
|
throw new Error("Failed to find user");
|
||||||
}
|
}
|
||||||
@@ -155,12 +159,16 @@ export const authLoginServiceFactory = ({ userDAL, tokenService, smtpService }:
|
|||||||
*/
|
*/
|
||||||
const loginExchangeClientProof = async ({
|
const loginExchangeClientProof = async ({
|
||||||
email,
|
email,
|
||||||
|
userOrgId,
|
||||||
clientProof,
|
clientProof,
|
||||||
providerAuthToken,
|
providerAuthToken,
|
||||||
ip,
|
ip,
|
||||||
userAgent
|
userAgent
|
||||||
}: TLoginClientProofDTO) => {
|
}: TLoginClientProofDTO) => {
|
||||||
const userEnc = await userDAL.findUserEncKeyByUsername(email);
|
const userEnc = await userDAL.findUserEncKeyByUsername({
|
||||||
|
username: email,
|
||||||
|
orgId: userOrgId
|
||||||
|
});
|
||||||
if (!userEnc) throw new Error("Failed to find user");
|
if (!userEnc) throw new Error("Failed to find user");
|
||||||
const cfg = getConfig();
|
const cfg = getConfig();
|
||||||
|
|
||||||
|
|||||||
@@ -2,12 +2,14 @@ import { AuthMethod } from "./auth-type";
|
|||||||
|
|
||||||
export type TLoginGenServerPublicKeyDTO = {
|
export type TLoginGenServerPublicKeyDTO = {
|
||||||
email: string;
|
email: string;
|
||||||
|
userOrgId?: string;
|
||||||
clientPublicKey: string;
|
clientPublicKey: string;
|
||||||
providerAuthToken?: string;
|
providerAuthToken?: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export type TLoginClientProofDTO = {
|
export type TLoginClientProofDTO = {
|
||||||
email: string;
|
email: string;
|
||||||
|
userOrgId?: string;
|
||||||
clientProof: string;
|
clientProof: string;
|
||||||
providerAuthToken?: string;
|
providerAuthToken?: string;
|
||||||
ip: string;
|
ip: string;
|
||||||
|
|||||||
@@ -20,10 +20,14 @@ export const userDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
// USER ENCRYPTION FUNCTIONS
|
// USER ENCRYPTION FUNCTIONS
|
||||||
// -------------------------
|
// -------------------------
|
||||||
const findUserEncKeyByUsername = async (username: string) => {
|
const findUserEncKeyByUsername = async ({ username, orgId }: { username: string; orgId?: string }) => {
|
||||||
try {
|
try {
|
||||||
return await db(TableName.Users)
|
return await db(TableName.Users)
|
||||||
.where({ username, isGhost: false })
|
.where({
|
||||||
|
username,
|
||||||
|
...(orgId ? { orgId } : { orgId: null }),
|
||||||
|
isGhost: false
|
||||||
|
})
|
||||||
.join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`)
|
.join(TableName.UserEncryptionKey, `${TableName.Users}.id`, `${TableName.UserEncryptionKey}.userId`)
|
||||||
.first();
|
.first();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
@@ -21,10 +21,12 @@ interface IsLoginSuccessful {
|
|||||||
*/
|
*/
|
||||||
const attemptLogin = async ({
|
const attemptLogin = async ({
|
||||||
email,
|
email,
|
||||||
|
orgId,
|
||||||
password,
|
password,
|
||||||
providerAuthToken
|
providerAuthToken
|
||||||
}: {
|
}: {
|
||||||
email: string;
|
email: string;
|
||||||
|
orgId?: string;
|
||||||
password: string;
|
password: string;
|
||||||
providerAuthToken?: string;
|
providerAuthToken?: string;
|
||||||
}): Promise<IsLoginSuccessful> => {
|
}): Promise<IsLoginSuccessful> => {
|
||||||
@@ -38,6 +40,7 @@ const attemptLogin = async ({
|
|||||||
|
|
||||||
const { serverPublicKey, salt } = await login1({
|
const { serverPublicKey, salt } = await login1({
|
||||||
email,
|
email,
|
||||||
|
orgId,
|
||||||
clientPublicKey,
|
clientPublicKey,
|
||||||
providerAuthToken
|
providerAuthToken
|
||||||
});
|
});
|
||||||
@@ -59,6 +62,7 @@ const attemptLogin = async ({
|
|||||||
tag
|
tag
|
||||||
} = await login2({
|
} = await login2({
|
||||||
email,
|
email,
|
||||||
|
orgId,
|
||||||
clientProof,
|
clientProof,
|
||||||
providerAuthToken
|
providerAuthToken
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -25,12 +25,14 @@ export type VerifyMfaTokenRes = {
|
|||||||
|
|
||||||
export type Login1DTO = {
|
export type Login1DTO = {
|
||||||
email: string;
|
email: string;
|
||||||
|
orgId?: string;
|
||||||
clientPublicKey: string;
|
clientPublicKey: string;
|
||||||
providerAuthToken?: string;
|
providerAuthToken?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
export type Login2DTO = {
|
export type Login2DTO = {
|
||||||
email: string;
|
email: string;
|
||||||
|
orgId?: string;
|
||||||
clientProof: string;
|
clientProof: string;
|
||||||
providerAuthToken?: string;
|
providerAuthToken?: string;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -78,6 +78,7 @@ export const PasswordStep = ({
|
|||||||
} else {
|
} else {
|
||||||
const loginAttempt = await attemptLogin({
|
const loginAttempt = await attemptLogin({
|
||||||
email,
|
email,
|
||||||
|
orgId: organizationId,
|
||||||
password,
|
password,
|
||||||
providerAuthToken,
|
providerAuthToken,
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user